Document Library Lite [document-library-lite] <= 1.1.7 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Barn2 Plugins Document Library Lite document-library-lite allows DOM-Based XSS.This issue affects Document Library Lite: from n/a through <= 1.1.7.
- Affected:
- up to 1.1.7
- Fix:
- No patched version reported
- Disclosed:
- Dec 16, 2025
CVE-2025-67986 on NVD →
Document Library Lite [document-library-lite] <= 1.1.7 (unfixed)
unknown
[en] Authorization Bypass Through User-Controlled Key vulnerability in Barn2 Plugins Document Library Lite document-library-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Document Library Lite: from n/a through <= 1.1.7.
- Affected:
- up to 1.1.7
- Fix:
- No patched version reported
- Disclosed:
- Dec 16, 2025
CVE-2025-67985 on NVD →
Document Library Lite <= 1.1.7 - Unauthenticated Insecure Direct Object Reference
medium
The Document Library Lite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.7. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 1.1.7
- Fixed in:
- 1.2.0
- Disclosed:
- Dec 15, 2025
CVE-2025-67985 on NVD →
Document Library Lite <= 1.1.7 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Document Library Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts i...
- CVSS:
- 4.4
- Affected:
- up to 1.1.7
- Fixed in:
- 1.2.0
- Disclosed:
- Dec 15, 2025
CVE-2025-67986 on NVD →
Document Library Lite [document-library-lite] < 1.1.7
unknown
[en] The Document Library Lite plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 1.1.6. This is due to the plugin exposing an unauthenticated AJAX action dll_load_posts which returns a JSON table of document data without performing nonce or capability checks. The handler...
- Affected:
- up to 1.1.7
- Fixed in:
- 1.1.7
- Disclosed:
- Nov 1, 2025
CVE-2025-11174 on NVD →
Document Library Lite <= 1.1.6 - Missing Authorization to Sensitive Information Exposure
medium
The Document Library Lite plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 1.1.6. This is due to the plugin exposing an unauthenticated AJAX action dll_load_posts which returns a JSON table of document data without performing nonce or capability checks. The handler acce...
- CVSS:
- 5.3
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.7
- Disclosed:
- Oct 31, 2025
CVE-2025-11174 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database